This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Homepage keeps changing Think I've been hijacked

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here's that logfile from the 22nd Aug, done as soon as the homepage had been changed again ….which was about 7 hours after the reboot.

Logfile of HijackThis v1.99.1
Scan saved at 2:22:52 PM, on 22/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Vet\isafe.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Vet\VetTray.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\rundll32.exe
C:\Vet\VetMsg.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Browser Hijack Blaster\bhblaster.exe
C:\Program Files\Paint Shop Pro\Psp.exe
C:\HIJACK THIS\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\Vet\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Vet\VetMsg.exe



I'm not sure how much good that will be now though, so here's one I did more recently, since your last lot of instructions.

Just to clarify….in my last post I posted the one done straight after reboot, taken at 3:20:36 PM, on 1st Sept 2005….when homepage was back to Google and IE Advanced Options were back to my preferred settings.

And the one below is one I took the following day at 8:05:27 AM, on 2nd Sept 2005….AFTER I got the message again to say that the homepage had been changed.

Logfile of HijackThis v1.99.1
Scan saved at 8:05:27 AM, on 2/09/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Vet\VetTray.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Vet\isafe.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Vet\VetMsg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Browser Hijack Blaster\bhblaster.exe
C:\PROGRA~1\PAINTS~1\Psp.exe
C:\HIJACK THIS\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B78407D-1BB9-4A39-938D-844E8294C4A3}: NameServer = 203.49.70.20 139.134.2.190
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\Vet\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Vet\VetMsg.exe



One other point….I think I already told you that after the homepage has been changed, things have also changed in my IE Advanced settings and the box that says "Reuse windows for launching shortcuts" has been ticked (I keep it unticked because I like new links to open in new windows). Right….yesterday, after the homepage had been changed again, I noticed another setting had been changed as well, the box that says "Enable Install on Demand" had been ticked. (This might have been happening all the time but I only noticed it yesterday).

I don't even pretend to know what all these settings mean exactly but I find this a bit scary. I don't like the idea of anything getting downloaded automatically onto my computer without my knowledge or permission….even if it IS only so the webpage will display correctly or whatever that blurb means.

When things are running normally (meaning that the homepage has not yet got changed in that particular session), I sometimes get a message (which I assume comes from SpywareBlaster) telling me that the webpage might not display correctly because of my security settings, something to do with ActiveX.

Now I'm worried that having that setting ticked will override SpywareBlaster and allow this to happen and ActiveX stuff will be able to be run. Am I understanding this correctly? Should I be getting straight off the internet as soon as the homepage has been changed to avoid possible download of something nasty?

Btw, once the homepagehas been changed, my going in and unticking those boxes has no effect because it doesn't stick. To set them in place again, I have to log off, reboot, log on again, then untick them….and then they stick until the message comes to say the home page has been changed again.


Editing Upon re-reading my post, I have noticed there is a link in those logs above. This one: http://download.games.yahoo.com/games/web_…aploader_v6.cab

What the heck is that doing there in my registry??? Especially as I allowed Ewido to get rid of the Yahoo PopCap thingy (that I had assumed was to do with my playing of games at Yahoo) when I ran it the second time. I have not been back playing that game since then and haven't even been into Yahoo games at all.

Chris.
Here it is: Find Qoologic last edited 9/02/2005 PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. some examples are MRT.EXE NTDLL.DLL. »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»» (fstarts by IMM - test ver. 0.001) NOT using address check – 0x77f75fae Global Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup . .. desktop.ini WinZip Quick Pick.lnk User Startup: C:\Documents and Settings\Chris\Start Menu\Programs\Startup . .. desktop.ini »»»»» Search by size and name… »»»»» Files found by this method are not necessarily bad… »»»»» Example PNGFILT.DLL ctl3d32.dll are windows files… Chris.
Please check your ActiveX security settings. They may have been changed by this CWS variant to allow ALL ActiveX!! If they have been changed, reset your active x security settings in IE as recommended here: ActiveX controls and plug-ins * Download signed ActiveX controls (Prompt) * Download unsigned ActiveX controls (Disable) * Initialize and script ActiveX controls not marked as safe (Disable) * Run ActiveX controls and plug-ins (Enabled) (This actually refers to Java and Flash, not ActiveX) * Script ActiveX controls marked safe for scripting (Prompt)
I've just checked them all now and they are okay…but I haven't had *that* message yet. I must remember to check again after the homepage gets changed next. I don't recall ever manually choosing the ActiveX settings I have, (because I don't really understand exactly what I'm doing in this area) but all of the ones you mentioned were already set to Disable. Could this have been set in place by Spyware Blaster? You didn't say whether Find Qoologic gave you any useful information. Have you been able to ascertain for sure what it is that got into my system? And is it removable? Chris.

C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\724ZJXSL\popcaploader_v6[1].spl/PopCapLoader.dll -> Not-A-Virus.PornWare.PopCap.b

: Something is causing this to load from the internet.


Go here and do a online scan. Be sure to select clean or fix if it's a option.
TrendMicro HouseCall
I've checked my system with Housecall and it found nothing but I'm not sure if everything worked as it should have. :unsure:

When I went to do it, I had to agree to having some ActiveX thing installed, (which meant I had to change the ActiveX security settings so I changed them from all being disabled to what you had advised in your post above). But as soon as I gave the ok to Housecall to install its thing, SpyBot popped up querying something (I forget the exact wording) so, not knowing what to do, I clicked on the question mark beside where it said Remember this decision (which was the only option there was apart from ticking that box) to see what it was all about and SpyBot's Help window came up but it was half covered by the Housecall Install window which wouldn't go away (and I couldn't move it) so I couldn't scroll down to read the Help file properly anyway.

So I gave up on that idea and just checked Spybot's message box where it said Remember this decision, and then there was a message saying a registry value had changed and was it ok sort of thing and I said Yes, (thinking it must be something Housecall was doing) and the Spybot box was still there with the Remember this decision box still ticked and looking at me stupidly as if waiting for some more input :blink: but there was nothing else to tick and no OK button or anything so I hit Enter to make it go away and then a very small window popped up saying something about registry change being denied but it was so quick I hardly had time to read it. By then Housecall reckoned it had been given the green light and stuff was downloading so I just let it go

There didn't seem to be a problem with running the scan and it said it didn't find anything but I don't know what the deal was with querying the registry value change and then getting the other popup saying the change had been denied. If this was something Housecall needed to do in order to run a proper scan and it was denied, then would the scan have worked as it should have? :scratch:

Sorry to rattle on, but I have no clue about these things so I'm treating you like the cops and telling you averything I can remember whether it seems important or not….just in case it is.

Chris.
What version of SpyBot are you using?
SpyBot's TeaTimer program is the one that tells you if changes are being made.



Backup your Registry…
- Press "CTRL - ALT - DEL" keys all at the same time to start "Task Manager"
- In the Task Manager window click on "File", then from the drop-down menu select "New Task (Run…)"
- In the "Create New Task" window enter\type "regedit" (without quotes)
- Once Regedit opens click on the FILE menu and select Export
- Save the file as backup. Save the file somewhere you will remember and not delete.
IMPORTANT: make sure to set the export range to ALL



click Start>Run and type regedit tap enter key.


Regedit will open. Make sure My Computer is highlighted. At the top of the window click edit> Find> then copy and paste the following into the window.

PopCap

Then click find now.
When you find the entry right click on it and select delete, answer ok at the prompt.
Next, press "F3" to continue searching, if another instance is found, repeat the above steps, until you see the "completed searching" message.

Let me know if anything is found.
I have SpyBot Version 1.4. TeaTimer…yes…I think I finally have my head around it and what it does. I've only recently enabled it, (since this problem with the changing homepage started) and I can't really remember why I never did before but I think it was because I had the idea that I had to have a paid for version of SpyBot to get that option, or something. I think I see now why it gave that message yesterday when I was running Housecall. It would have been because Housecall needs to do something with ActiveX in order to run and, of course, TeaTimer didn't like that and sent the message. But if TeaTimer was doing its job properly and not allowing the registry change to be made (which it appeared to do, seeing it said it was denied) then would Housecall have been able to override that and install what it needed? And if if couldn't, would the scan still have run properly? Should I disable TeaTimer and run Housecall again? Sorry to be such a pain, but my head is spinning trying to figure all this out and it's very confusing. Sometimes I just want to sit in the corner and cry. Okay…. following your latest instructions, I backed up the registry and searched for PopCap and found two instances of it which I deleted. Then I rebooted. After this, I went into SpyBot to have a proper read about all its tools and what they do and when I was looking at the list of ActiveX thingies, I saw that there was a PopCap one there so I thought I had best delete it. But then I got that TeaTimer message saying the change was denied….and it was only then that I twigged as to what that same message had been about when I was doing the Housecall scan. So then I disabled all of SpyBot's resident protection (both TeaTimer and the other one, forget what it's called) and deleted the PopCap ActiveX thing, and then re-enabled them both, and rebooted. I am writing this from the old computer and leaving the new one run to see if I still get the homepage changed. This happens even if I'm not online. But I still don't think that PopCap is the culprit unless they have a newer version of it that does this nasty stuff. As I told you once before, it's on my old computer and was installed in order to play certain Yahoo games, it's been there for ages, and the computer is running fine. I ran regedit on it just before, and found quite a lot of instances of PopCap and they don't seem to be doing anything bad. I'll get back to you when/if the new computer's homepage gets changed again. (Or even if it doesn't after the computer has run for about 10 hours….which would be miracle and would hopefully mean the problem has been removed.) Chris.
I still got the message that the homepage had been changed, about 6 hours after reboot. I hadn't been online or done anything else on the computer.

Some new strange things have come to my notice since getting rid of PopCap. I had been checking the Tools in SpyBot and seeing just what was listed in the various windows and when I checked the ActiveX window, I was surprised to see a new entry….3rd on the list in the pic below, where the PopCap one had been before I got rid of it yesterday.

[external image: Posted Image]


and this is what you see when you click on it

[external image: Posted Image]

I had no clue what this was and figured it didn't belong there, so I used the option in SpyBot to delete it….but it came back after a reboot. And I've deleted it several times since then but it's always back after a reboot. I have just deleted it again now before logging on, *just in case*.

Now this next thing may or may not have anything to do with the general problem but when I go to reboot or shut down now, I get a message that TeaTimer.exe is being ended and then I have to choose End Now or wait until I get the new box that gives a choice of End or Cancel before the computer will shut down. I still get this message even if I go into SpyBot and disable TeaTimer before I try to shut down.

This was not happening before and I've had TeaTimer running for several weeks now. Also have it on the old computer and I can reboot or shut it down without getting this message. Do you think that SpyBot has got corrupted and that I should reinstall it?

I haven't thanked you lately for all the effort you're putting into this so I'll say it now. THANK YOU! You're a legend. :thumbup:

Chris.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI